Received: by 2002:a05:6a10:8c0a:0:0:0:0 with SMTP id go10csp2680031pxb; Tue, 23 Feb 2021 12:50:48 -0800 (PST) X-Google-Smtp-Source: ABdhPJy5TuRXGUY0J5ULa08bqNwZeIBN9hDB4xHA7ZkCRX6EVBX2vTD3C89+sC9lBPrbY07XkZXA X-Received: by 2002:a17:906:2c44:: with SMTP id f4mr10523439ejh.234.1614113447901; Tue, 23 Feb 2021 12:50:47 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1614113447; cv=none; d=google.com; s=arc-20160816; b=snYiQJrOwDPFoxx2RcnNvxORF8BDbLJDXdjJNp0On9TTMP8dBgysnGpJ9zphdvES0y zQEUtIG0zzO1o51QH3sGI5mKry/OfZ0c2W+0zPM6eBDtqERN3nB1MT8h3Dmt03FdQ4nq yrJTStv8WTTXnSaJyeitprLjsyvVHgdW8sJRK8raU5dT7mwpYYviamjR8eUDlIR3tMLD Fq4I+n//tNx1A6gWMf+UZfTvDBg9KJm4w2p/zxUUVdf6C9jp/QRwZkh3PMjSYHm8B8Un C59pGhhP9xUsUX+i5eHTWiF1BB/eeOavbhUTOSlirHj7tg07wPAJry97Sb7B94jiS6n1 ouWw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:content-language :in-reply-to:mime-version:user-agent:date:message-id:from:references :cc:to:subject:dkim-signature:dkim-filter; bh=bgVREtbThCXyyNVzI6besUKkeZ3w63oXLPzE3PrY3pg=; b=RHucNmo18G4JpuISpIBn1kdm/odp1bFL5WvWxnPMsvlisS9ZaykwudHQ2Tin7Ce61A mUGwJlPtotKw6Y4nwQs8i4Gg+yPFHxJdAleIDgN3HuXuLrCDCGo3EdNGTmxWl5PWv9Ak qSmR9Z2dmnbb6E6e9QCDuAlh9YklEvHtfktoarJisro+Eyx0JtxTzVGYMZRkJiHrYiPi iZUQtomeUxA8yFhQt5x8+cdizqINMxbPD1jUSFgxxueK3RKTBk7j0s4m1UTXYJyCFB5e 1MmJu8QtZPYB8mMUBzroI6eJgx6HsQipcawKO87EbqyyKl7SdsAsBx3PrC/luINIwy/5 039Q== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linux.microsoft.com header.s=default header.b=Ro2SNAFV; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linux.microsoft.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id h24si8886555edv.333.2021.02.23.12.50.22; Tue, 23 Feb 2021 12:50:47 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@linux.microsoft.com header.s=default header.b=Ro2SNAFV; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linux.microsoft.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231414AbhBWTXW (ORCPT + 99 others); Tue, 23 Feb 2021 14:23:22 -0500 Received: from linux.microsoft.com ([13.77.154.182]:41214 "EHLO linux.microsoft.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S233995AbhBWTVb (ORCPT ); Tue, 23 Feb 2021 14:21:31 -0500 Received: from [192.168.254.32] (unknown [47.187.194.202]) by linux.microsoft.com (Postfix) with ESMTPSA id 451ED20B6C40; Tue, 23 Feb 2021 11:20:50 -0800 (PST) DKIM-Filter: OpenDKIM Filter v2.11.0 linux.microsoft.com 451ED20B6C40 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.microsoft.com; s=default; t=1614108050; bh=bgVREtbThCXyyNVzI6besUKkeZ3w63oXLPzE3PrY3pg=; h=Subject:To:Cc:References:From:Date:In-Reply-To:From; b=Ro2SNAFV/9dYuQbu/CjgaupoR8BXXeFbt/T1IF29ETKMMSFV5PUCPjxTQxgWVvWky EEhrkZ+OpfQ3TrkVrT2gd4x1EKYGbYxTJBWpd01fbhyNYGXxQzmzZReTHR6aqxpBdw 7QIGdAHiLRcLUOHBX0I4UoCLFvpcm3ZUhGKOpbDU= Subject: Re: [RFC PATCH v1 1/1] arm64: Unwinder enhancements for reliable stack trace To: Mark Brown Cc: mark.rutland@arm.com, jpoimboe@redhat.com, jthierry@redhat.com, linux-arm-kernel@lists.infradead.org, live-patching@vger.kernel.org, linux-kernel@vger.kernel.org References: <20210223181243.6776-1-madvenka@linux.microsoft.com> <20210223181243.6776-2-madvenka@linux.microsoft.com> <20210223190240.GK5116@sirena.org.uk> From: "Madhavan T. Venkataraman" Message-ID: <08e8e02c-8ef0-26bb-1d0d-7dda54b5fefd@linux.microsoft.com> Date: Tue, 23 Feb 2021 13:20:49 -0600 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.10.0 MIME-Version: 1.0 In-Reply-To: <20210223190240.GK5116@sirena.org.uk> Content-Type: text/plain; charset=windows-1252 Content-Language: en-US Content-Transfer-Encoding: 7bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 2/23/21 1:02 PM, Mark Brown wrote: > On Tue, Feb 23, 2021 at 12:12:43PM -0600, madvenka@linux.microsoft.com wrote: >> From: "Madhavan T. Venkataraman" >> >> Unwinder changes >> ================ > > This is making several different changes so should be split into a patch > series - for example the change to terminate on a specific function > pointer rather than NULL and the changes to the exception/interupt > detection should be split. Please see submitting-patches.rst for some > discussion about how to split things up. In general if you've got a > changelog enumerating a number of different changes in a patch that's a > warning sign that it might be good split things up. > Will do. > You should also copy the architecture maintainers (Catalin and Will) on > any arch/arm64 submissions. > Will do when I resubmit. >> Unwinder return value >> ===================== >> >> Currently, the unwinder returns -EINVAL for stack trace termination >> as well as stack trace error. Return -ENOENT for stack trace >> termination and -EINVAL for error to disambiguate. This idea has >> been borrowed from Mark Brown. > > You could just include my patch for this in your series. > OK. >> Reliable stack trace function >> ============================= >> >> Implement arch_stack_walk_reliable(). This function walks the stack like >> the existing stack trace functions with a couple of additional checks: >> >> Return address check >> -------------------- >> >> For each frame, check the return address to see if it is a >> proper kernel text address. If not, return -EINVAL. >> >> Exception frame check >> --------------------- >> >> Check each frame to see if it is an EL1 exception frame. If it is, >> return -EINVAL. > > Again, this should be at least one separate patch. How does this ensure > that we don't have any issues with any of the various probe mechanisms? > If there's no need to explicitly check anything that should be called > out in the changelog. > I am trying to do this in an incremental fashion. I have to study the probe mechanisms a little bit more before I can come up with a solution. But if you want to see that addressed in this patch set, I could do that. It will take a little bit of time. That is all. > Since all these changes are mixed up this is a fairly superficial > review of the actual code. > Understood. I will split things up and we can take it from there. >> +static notrace struct pt_regs *get_frame_regs(struct task_struct *task, >> + struct stackframe *frame) >> +{ >> + unsigned long stackframe, regs_start, regs_end; >> + struct stack_info info; >> + >> + stackframe = frame->prev_fp; >> + if (!stackframe) >> + return NULL; >> + >> + (void) on_accessible_stack(task, stackframe, &info); > > Shouldn't we return NULL if we are not on an accessible stack? > The prev_fp has already been checked by the unwinder in the previous frame. That is why I don't check the return value. If that is acceptable, I will add a comment. >> +static notrace int update_frame(struct task_struct *task, >> + struct stackframe *frame) > > This function really needs some documentation, the function is just > called update_frame() which doesn't say what sort of updates it's > supposed to do and most of the checks aren't explained, not all of them > are super obvious. > I will add the documentation as well as try think of a better name. >> +{ >> + unsigned long lsb = frame->fp & 0xf; >> + unsigned long fp = frame->fp & ~lsb; >> + unsigned long pc = frame->pc; >> + struct pt_regs *regs; >> + >> + frame->exception_frame = false; >> + >> + if (fp == (unsigned long) arm64_last_frame && >> + pc == (unsigned long) arm64_last_func) >> + return -ENOENT; >> + >> + if (!lsb) >> + return 0; >> + if (lsb != 1) >> + return -EINVAL; >> + >> + /* >> + * This looks like an EL1 exception frame. > > For clarity it would be good to spell out the properties of an EL1 > exception frame. It is not clear to me why we don't reference the frame > type information the unwinder already records as part of these checks. > > In general, especially for the bits specific to reliable stack trace, I > think we want to err on the side of verbosity here so that it is crystal > clear what all the checks are supposed to be doing and it's that much > easier to tie everything through to the requirements document. OK. I will improve the documentation. Madhavan